Junglewise Threat Intelligence

CVE-2026-18201: Red Hat Keycloak improper authorization in identity-provider REST endpoint

CVE-2026-18201 · Severity: medium · CVSS 5.5 · Published 2026-07-29

Technologies: Red Hat Keycloak. Vendors: Red Hat.

Executive brief

Keycloak is an open-source identity and access management solution used to secure modern applications and services. A security flaw was found where an administrator with limited permissions could link a new login provider to a specific organization without having the proper authorization to manage that organization. This could allow an unauthorized administrator to change how users log into specific business units or organizations, potentially leading to unauthorized access or disruption of the login process.

Technical details

An authorization bypass exists in the Keycloak generic identity-provider REST endpoint (/admin/realms/{realm}/identity-provider/instances). While organization-scoped endpoints correctly enforce both 'manage-identity-providers' and 'manage-organizations' permissions, the generic endpoint fails to verify the 'manage-organizations' permission when an 'organizationId' is included in the request payload. An attacker with administrative access to manage identity providers can exploit this to bind brokers to organizations they do not control. Furthermore, this exploit path bypasses organization IdP-list cache invalidation, causing a discrepancy between the actual configuration and cached listings.

Affected products

  • Red Hat Keycloak unspecified

Timeline

  • 2026-07-29: disclosed: Vulnerability reported via Red Hat Bugzilla and NVD.
  • 2026-07-29: advisory

References